Snort mailing list archives

Re: icmp


From: Guillaume <guillaume () anteria fr>
Date: Thu, 15 Nov 2001 09:25:08 +0100 (CET)

En réponse à Ryan Russell <ryan () securityfocus com>:

On Wed, 14 Nov 2001, Peter VE wrote:

All I wanted to achieve is to fool the remote users, letting them
believe my host is unreachable for icmp traffic...

Normal behavior for ICMP to a host that doesn't allow it is no
response.


Well... Let's say it is a normal behavio(u)r for a firewall admin to disable
ICMP responses !!
The normal behavio(u)r of a host that does not allow ICMP messages is to send a
"destination host administratively prohibited" or something like that...

Regards,

Guillaume.

**********************************
Sent with HORDE/IMP

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: